{"id":"MAL-2025-191503","summary":"Malicious code in start-internal (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (191a0cd368d9612b95c373551c4e8e15faac47d990feaba41964d85e4eff4b09)\nThe package start-internal was found to contain malicious code.\n","modified":"2025-12-24T10:30:42.255657Z","published":"2025-12-01T16:00:47Z","database_specific":{"malicious-packages-origins":[{"import_time":"2025-12-01T16:09:25.858373579Z","modified_time":"2025-12-01T16:00:47Z","ranges":[{"events":[{"introduced":"0"}],"type":"SEMVER"}],"sha256":"191a0cd368d9612b95c373551c4e8e15faac47d990feaba41964d85e4eff4b09","source":"amazon-inspector"},{"source":"reversing-labs","versions":["0.0.1","99.9.9"],"id":"RLMA-2025-06489","import_time":"2025-12-24T10:07:27.897153437Z","modified_time":"2025-12-23T08:31:20Z","sha256":"83e44c6f875c0ac88a10c81749d33322e51a58f19706a1c3d60c6f163b605ec6"}]},"affected":[{"package":{"name":"start-internal","ecosystem":"npm","purl":"pkg:npm/start-internal"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"versions":["0.0.1","99.9.9"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/start-internal/MAL-2025-191503.json"}}],"schema_version":"1.7.3","credits":[{"name":"Amazon Inspector","contact":["actran@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}